Improper Restriction of Excessive Authentication Attempts in Siemens products - CVE-2022-24044
Published: May 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the login functionality of the application does not employ any countermeasures against Password Spraying attacks or Credential Stuffing attacks. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Desigo DXR2
Desigo PXC4
Desigo PXC5
How to mitigate CVE-2022-24044
Desigo DXR2 - update to 01.21.142.5-22
Desigo PXC4 - update to 02.20.142.10-10884
Desigo PXC5 - update to 02.20.142.10-10884